CVE-2026-98367

Source
https://cve.org/CVERecord?id=CVE-2026-98367
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98367.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98367
Downstream
Published
2026-10-06T08:46:52Z
Modified
2026-10-08T02:52:58Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept

We need to clear cep before release state_lock as siw_qp_llp_close and siw_qp_modify->siw_qp_llp_close did.

Otherwise if siw_qp_modify() fails in siw_accept(), the QP's state_lock is released before the error path cleanup. A concurrent ibv_modify_qp() transitioning the QP to ERROR can race in this window:

siw_accept() ibv_modify_qp(ERROR)


siw_qp_modify() fails up_write(&qp->state_lock) down_write(&qp->state_lock) nextstate_from_idle(): if (qp->cep) siw_cep_put(qp->cep) <- frees cep qp->cep = NULL goto error cep->qp = NULL <- UAF

Clear qp->cep and drop the association reference taken by siw_cep_get(), all under the write lock held from the initial down_write(&qp->state_lock). Thread B therefore sees qp->cep == NULL, skips its own put, and cannot free the cep before siw_accept() is done with it.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98367.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6c52fdc244b5ccc468006fd65a504d4ee33743c7
Fixed
f11e09fe2fc3a11ccdf8f932b68181b0bb1d2078
Fixed
e3f039082856adab7e195dea1af45d93dd6a3f1c
Fixed
ad50d19f3d1ce052b3a146143581e930a1efb33e
Fixed
030306bbb9273af80f14d7af20129661964cd9a7
Fixed
df2584750314336edcbcc21fb388e04b260f35b7
Fixed
9dcc0f4e488b70cff81e0e5717a498c929cf5de3
Fixed
bfdc744bf20ae4c3ef2e470298de5237c5c9a13c
Fixed
32cd87f54dd1070020e664ccb0312a9f0fea79b4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98367.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.3.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98367.json"